MANUAL IN TERMS OF THE PROMOTION OF ACCESS TO INFORMATION ACT 2 OF 2000 (PAIA) AND THE PROTECTION OF PERSONAL INFORMATION ACT 4 OF 2013 (POPIA)

Effective Date: 7 September 2025

FOR: MEMETY TRADING CC t/a DŌTUM.NET

1. Introduction and Purpose of this Manual

This manual is prepared in accordance with Section 51 of the Promotion of Access to Information Act 2 of 2000 ("PAIA"), as amended, and incorporates the requirements of the Protection of Personal Information Act 4 of 2013 ("POPIA"). PAIA gives effect to the constitutional right of access to information, as provided for in Section 32 of the Constitution of the Republic of South Africa, 1996.

However, this right is subject to justifiable limitations, including the reasonable protection of privacy, commercial confidentiality, and effective governance. This manual serves to inform the public about the categories of information held by Memety Trading CC t/a Dōtum.net ("Dōtum") and to detail the formal, legally mandated procedures that must be followed to request access to any of its records.

The purpose of this manual is therefore twofold:

This document should be understood not as an open invitation for information but as a guide to a formal, legally-gated process, which balances the right of access with the rights of Dōtum and third parties.

2. Contact Details of Memety Trading CC t/a Dōtum.net (Section 51(1)(a))

This section provides the necessary contact details for Dōtum in compliance with Section 51(1)(a) of PAIA. All formal requests for access to information under PAIA must be directed to the general PAIA email address. All other queries related to data protection or this manual must be directed to the Information Officer. This centralisation of requests is a critical operational control to ensure that all PAIA and POPIA matters are handled consistently, formally, and within the prescribed legal timeframes.

Full Name of Private Body: Memety Trading CC t/a Dōtum.net

Registration Number, Physical Address, and Postal Address: These details are available upon submission of a valid request.

Website: www.dotum.net

General PAIA Requests Email: paia [at] dotum.net

Information Officer

The Head of the private body is the designated Information Officer.

Email for all POPIA/Privacy matters: privacy [at] dotum.net

3. The Information Regulator's Guide on How to Use PAIA (Section 51(1)(b)(i))

In terms of Section 10 of PAIA, the Information Regulator of South Africa has published a guide to assist individuals in exercising their rights under the Act. This guide contains comprehensive information regarding the objects of PAIA and POPIA, the procedures for submitting requests, and the remedies available in law should a request be denied. By providing these details, Dōtum affirms its commitment to operating within the established regulatory framework and acknowledges the oversight role of the Information Regulator.

The guide is available from the Information Regulator, whose contact details are as follows:

Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Postal Address: P.O. Box 31533, Braamfontein, Johannesburg, 2017

Website: www.inforegulator.org.za

General Enquiries Email: enquiries [at] inforegulator.org.za

PAIA Complaints Email: PAIAComplaints [at] inforegulator.org.za

4. Records Available in Accordance with Other Legislation (Section 51(1)(b)(iii))

Dōtum holds certain records in accordance with other South African legislation, as mandated by Section 51(1)(b)(iii) of PAIA. The availability of these records is subject to the provisions, including any confidentiality clauses, of the respective Acts. This list demonstrates that many records are governed by specific statutory requirements, reinforcing the principle that access is not automatic and may be subject to other legal protections.

Applicable Legislation Category of Records
Basic Conditions of Employment Act 75 of 1997 Employee records, Employment contracts
Companies Act 71 of 2008 Company incorporation documents, Register of members, Minutes of meetings
Compensation for Occupational Injuries and Diseases Act 130 of 1993 Records of employee injuries
Electronic Communications and Transactions Act 25 of 2002 Records of electronic communications and transactions
Income Tax Act 58 of 1962 Financial and tax records
Protection of Personal Information Act 4 of 2013 Records relating to the processing of personal information
Value-Added Tax Act 89 of 1991 VAT records and returns

5. Description of Subjects and Categories of Records Held (Section 51(1)(b)(iv))

In compliance with Section 51(1)(b)(iv) of PAIA, the following table provides a description of the subjects on which Dōtum holds records and the categories of records held on each subject. The examples provided under each category are illustrative and are furnished without limitation. These categories are defined in general terms to be legally sufficient while protecting the sensitive and proprietary nature of the information contained therein. This structure makes it more difficult for requesters to formulate overly broad or "fishing expedition" requests and provides the Information Officer with the necessary discretion to apply the grounds for refusal where appropriate.

Subject Categories of Records
Corporate Governance & Administration Company statutory records; Minutes of meetings; Internal policies and procedures; Records related to legal compliance.
Financial and Accounting Records Annual financial statements; Accounting records; Banking records; Invoices and statements; Tax records; Asset register.
Human Resources Employee records (including personal details, contracts, and leave records); Recruitment records; Payroll information; Disciplinary records; Training records.
Client and Prospective Client Engagement Client and prospective client contact and identity data; Client correspondence; Service proposals and quotations; Contracts and service level agreements; Service delivery and project records.
Supplier and Service Provider Management Supplier contracts and agreements; Supplier correspondence; Supplier database and contact details.
Information Technology IT policies and procedures; Software licensing agreements; Network and systems security records; Website analytics and usage data (as described in the Privacy Policy).
Intellectual Property Records pertaining to trademarks, copyrights, and source code owned by or licensed to Dōtum (as per Website Terms); Non-disclosure agreements.
Marketing and Communications Marketing materials; Website content; Records of user submissions and feedback (non-personal information).

6. Processing of Personal Information as per POPIA (Section 51(1)(c))

The amended Section 51 of PAIA requires the disclosure of information related to the processing of personal information. The following details are provided in alignment with Dōtum's Privacy Policy to ensure a consistent and legally coherent data governance narrative.

6.1 Purpose of Processing

Dōtum processes personal information for the following specific, explicit, and legitimate purposes:

6.2 Categories of Data Subjects and Personal Information

The following table outlines the categories of data subjects whose personal information Dōtum processes and the types of information processed for each.

Categories of Data Subjects Personal Information Processed
Website Visitors & Prospective Clients Identity & Contact Data (name, email, phone); Professional Data (company name, job title); Automatically Collected Technical Data (IP address, browser type, usage data).
Clients (Juristic and Natural Persons) Information required to fulfill contractual obligations, including contact, professional, and billing information.
Third-Party Service Providers Contact details and information necessary for the performance of contracted services.
Employees (As per Section 5) Personal details, employment history, financial information for payroll, etc.

6.3 Recipients of Personal Information

Dōtum does not sell, rent, or trade personal information. Information may be disclosed to the following categories of recipients:

Third-Party Service Providers: Trusted vendors engaged to perform functions on our behalf, who are contractually bound to confidentiality. This includes:

Legal Obligations: Disclosure may occur if required by law, subpoena, or other legal process to protect the rights, property, or safety of Dōtum, its clients, or the public.

6.4 Planned Transborder Flows of Personal Information

Personal information may be transferred to, and stored at, a destination outside of South Africa for specific operational purposes.

Where such transfers occur, Dōtum ensures that adequate data protection measures are in place to safeguard the information.

6.5 General Description of Information Security Measures

Dōtum has implemented appropriate technical and organizational security measures to safeguard personal information against accidental loss, unauthorized access, alteration, or disclosure. All client and website data is hosted on secure servers located within the Republic of South Africa.

7. Procedure for Requesting Access to Records (Section 53)

This section outlines the mandatory, formal procedure that a requester must follow to request access to a record held by Dōtum. Strict adherence to this procedure is required, and failure to comply will result in the request not being processed.

7.1 Form of Request

All requests for access must be made on the prescribed Form 2 - Request for Access to Record. This form is available on the Information Regulator's website. The form must be completed in full, and any incomplete or non-compliant submissions will be rejected on procedural grounds.

7.2 Requester's Burden of Justification

In accordance with Section 50 and Section 53(2)(d) of PAIA, a request for access to a record of a private body will only be considered if the record is required for the exercise or protection of a right. Therefore, the requester bears the burden of providing sufficient justification. The requester must:

A failure to provide a clear, substantive, and compelling explanation will render the request invalid and will be a primary ground for refusal. This is a critical, non-negotiable condition of the request process and serves as a proactive filter against speculative or unjustified requests.

7.3 Proof of Identity

The requester must submit a certified copy of their identification document to confirm their identity. If the request is made on behalf of another person, proof of the capacity in which the requester is acting must be provided to the reasonable satisfaction of the Information Officer.

7.4 Submission of Request

The fully completed Form 2, along with proof of identity, proof of authority (if applicable), and proof of payment of the request fee, must be submitted via email to paia [at] dotum.net.

7.5 Payment of Prescribed Fees

The following fees, prescribed in the PAIA regulations, are applicable to all requests. The inclusion of these fees reinforces the formal nature of the process and may deter frivolous requests. The fees listed below were correct at the date of publishing and will be amended as determined in law from time to time.

Item Description Fee (ZAR)
Request Fee A non-refundable fee payable by every requester with the submission of the request form. R140.00
Access Fees
Photocopy/Print (A4) For each page or part thereof. R2.00
Copy on Flash Drive Requester provides the drive. R40.00
Copy on CD Requester provides the CD. R40.00
Copy on CD Dōtum provides the CD. R60.00
Transcription of Audio Record For each A4 page or part thereof. R24.00
Search and Preparation Per hour or part thereof, reasonably required (the first hour is free). R145.00
Deposit If search and preparation is estimated to exceed 6 hours, one-third of the estimated access fee is payable upfront before the search commences. 1/3 of Estimate
Postage Actual cost of postage or courier services. At Cost

8. Grounds for Refusal of Access to Records (Chapter 4 of Part 3)

Dōtum will assess each validly submitted request on its individual merits. However, as a private body, Dōtum holds a significant amount of proprietary, confidential, and private information. Dōtum expressly reserves its right to refuse access to any record in accordance with the mandatory and discretionary grounds for refusal stipulated in Chapter 4 of PAIA. The primary position of Dōtum is that its records are proprietary and not subject to disclosure unless a requester can discharge the significant legal burden placed upon them by PAIA.

Key grounds for refusal include, but are not limited to, the following:

Section 63: Mandatory protection of the privacy of a third party. Access must be refused if disclosure would involve the unreasonable disclosure of personal information about a third party natural person.

Section 64: Mandatory protection of the commercial information of a third party. Access must be refused if a record contains trade secrets or other financial, commercial, scientific, or technical information of a third party, where disclosure would likely cause harm to their commercial or financial interests.

Section 65: Mandatory protection of confidential information of a third party. Access must be refused if disclosure would constitute a breach of a duty of confidence owed to a third party in terms of an agreement.

Section 66: Mandatory protection of the safety of individuals and property. Access must be refused if disclosure could reasonably be expected to endanger the life or physical safety of an individual or the security of property.

Section 67: Mandatory protection of records subject to legal privilege. Access must be refused if the record is privileged from production in legal proceedings, unless the privilege has been waived.

Section 68: Discretionary protection of Dōtum's commercial and proprietary information. As the vast majority of Dōtum's records contain commercially sensitive information, this ground will be broadly applied. Dōtum may refuse access to a record if it contains:

Section 69: Protection of research information. Access must be refused if a record contains research information belonging to Dōtum or a third party and its disclosure would be likely to expose the research or the researcher to serious disadvantage.

Furthermore, any request will be refused if the requester fails to provide an adequate explanation of why the requested record is required for the exercise or protection of a right, as stipulated in Section 7.2 of this manual.

9. Remedies Available upon Refusal of a Request

Should a request for access be denied, the requester has legal recourse. By clearly stating this process, Dōtum demonstrates its adherence to procedural fairness and its confidence that any refusal will be legally sound and capable of withstanding regulatory scrutiny.

A requester who is aggrieved by the decision of the Information Officer may lodge a complaint with the Information Regulator. The complaint must be submitted on the prescribed Form 5 and must be lodged within 180 days of the date of the decision. The contact details for the Information Regulator are provided in Section 3 of this manual.

10. Availability and Updating of the Manual

In accordance with Section 51(3) of PAIA, this manual is available as follows:

The public availability of this manual ensures that any potential requester has constructive knowledge of the strict procedures and legal grounds for refusal outlined herein before initiating a request. Dōtum cannot be held responsible for a requester's failure to familiarise themselves with these legally mandated requirements.

This manual will be updated on a regular basis as required by law.


© 2025 Dōtum.net (Pty) Ltd. All Rights Reserved.